PDF Metadata Examination Kenya · Digital & Document Forensics

The Contract Says 2019. The File Disagrees.

Every digital document carries a second, invisible record of its own history — one that isn’t written by whoever typed the visible text. PDF metadata examination in Kenya is how that hidden record gets read, and how backdated contracts and forged agreements get caught.

3Independent metadata sources per document type
106AEvidence Act standard for electronic records
0Alterations made during examination
In short

A digital document’s visible content and its actual history are recorded separately. PDF properties, Word’s internal revision structure, and a photograph’s EXIF data all capture when a file was truly created, edited, and saved — independent of whatever date appears in the printed or displayed text. PDF metadata examination in Kenya compares these hidden records against the document’s claimed date to establish whether a contract, agreement, or letter is genuine.

Why a Digital Document Can’t Fully Hide Its Own History

A paper document only shows what’s on the page. A digital one carries a second record most people never think to look at — created automatically by the software that produced it, without the author’s involvement or awareness. This is the foundation of PDF metadata examination in Kenya: comparing what a document claims about itself against what the file format was actually built to record.

This matters because the most common way a fabricated document gets caught isn’t a spelling mistake or an inconsistent signature — it’s a mismatch between the story the document tells and the story its own file structure tells. Three sources carry most of that story: PDF properties, Word’s internal revision data, and EXIF metadata in photographed signature pages.

📄

PDF Properties & Metadata

Every PDF embeds a Document Information Dictionary and often XMP metadata recording creation software, creation date, and modification history — set by the computer, not the author.

📝

Word Revision History

A .docx file is a compressed archive of XML parts. Author names, save timestamps, and sometimes prior revisions can persist inside that structure long after visible track changes are cleared.

📷

EXIF Data

Photos of signed signature pages — sent over WhatsApp or email — often carry a capture timestamp, device model, and sometimes GPS coordinates, independent of anything written on the page itself.

“You can retype a date. You cannot retype the moment your computer says the file was actually born.”

PDF Properties: What the Document Information Dictionary Reveals

Open the properties panel of almost any PDF and you’ll find a small set of fields most people ignore: Author, Producer, CreationDate, ModDate, and often the specific software version used to generate it. These fields are written automatically at the moment of export or save — a contract “created” using a version of Adobe Acrobat or Microsoft Word that didn’t exist yet at the claimed contract date is, on its own, close to conclusive.

Beyond the visible properties panel, many PDFs also carry XMP metadata — a more detailed, XML-based record embedded in the file that can include edit history, prior filenames, and the specific application and operating system used at each save. Where a PDF has gone through multiple saves or exports, XMP metadata can preserve a trail of those events even after the visible properties panel has been manually edited to show something else.

Anatomy of a Backdated PDF

What the Document Claims vs. What Its Properties Actually Record

A simplified, illustrative property panel — annotated the way an examiner reads it during a PDF metadata examination in Kenya.

Document text states:“Executed this 4th day of March, 2019”
CreationDate:2026-05-14 11:42:07POSTDATES CLAIM
ModDate:2026-05-14 11:47:52SAME-DAY EDIT WINDOW
Producer:Microsoft® Word for Microsoft 365VERSION DID NOT EXIST IN 2019
Author:DESKTOP-6XJ2P\\userDEVICE NAME UNRELATED TO SIGNATORY
XMP Edit History:2 prior save events detectedCONTRADICTS “ORIGINAL SCAN” CLAIM
FAIL Directly contradicts the document’s claimed history
WARN Inconsistent, needs corroboration
PASS Consistent with genuine timeline

Word Revision History: What Survives “Accept All Changes”

A .docx file is not a single block of text — it’s a ZIP archive containing multiple XML files that separately describe the document’s content, formatting, comments, and revision data. Clicking “Accept All Changes” removes the visible track-changes markup from the reading view, but it doesn’t always purge every trace of that history from the underlying file structure, especially where a document has been saved rather than freshly exported as a clean copy.

Examiners look specifically at the document’s internal author list — every account name that has ever edited the file, in what’s sometimes a longer list than the document’s visible signatories would suggest — alongside embedded save timestamps and, in some cases, remnants of deleted comments or prior paragraph versions. A contract whose internal author history includes a name entirely unconnected to either party, or whose earliest recorded edit postdates the agreement’s claimed signing date, raises exactly the kind of question a court or opposing counsel needs answered.

EXIF Data: When the “Original Signed Copy” Is Just a Photo

An enormous number of disputed agreements in Kenya don’t arrive as clean PDFs at all — they arrive as a photograph of a signed page, taken on a phone and sent over WhatsApp or email. That photograph carries its own metadata, called EXIF (Exchangeable Image File Format) data, which can include the exact date and time the photo was taken, the camera or phone model used, and — where location services were enabled — GPS coordinates for where the photo was captured.

This becomes significant when a photographed “original” signature page is claimed to have been signed at one time and place, but its EXIF capture timestamp — or the compression pattern typical of a specific messaging app’s re-encoding — tells a different story. Even where an image has been forwarded and re-compressed multiple times, forensic examination can often still establish the file lineage and, where original EXIF data survives, the true capture window.

Backdated Contracts: Reading the Three Sources Together

The strongest findings rarely rest on a single metadata field — they come from cross-referencing all three sources against each other and against any independent record available, such as email transmission logs, printer spool history, or a notary’s own diary. A contract that is internally consistent across PDF properties, Word revision history, and any accompanying photographed signature page is far harder to challenge than one relying on a single date claim alone. Conversely, even one clear contradiction — a creation date, an author name, or a capture timestamp that doesn’t fit the claimed story — is often enough to shift an entire dispute.

CROSS-CHECK 1

Software version against claimed date: does the Producer field name an application version that existed at the time the document was supposedly created?

CROSS-CHECK 2

Author identity against signatories: does the internal author or device name correspond to anyone actually party to the agreement?

CROSS-CHECK 3

Save/edit timeline against claimed signing date: do CreationDate, ModDate, and any embedded revision history sit before, on, or — critically — after the date written into the document text?

CROSS-CHECK 4

Transmission metadata against document metadata: do email headers or WhatsApp media timestamps corroborate or contradict the file’s own internal dates?

Forged Agreements: Where Metadata Meets Physical Examination

Many forged agreements aren’t created from scratch — they’re built by editing a genuine older document (reusing its letterhead, formatting, and reference numbers) and re-exporting it as a new PDF. This is precisely why PDF metadata examination is treated as a companion discipline to physical document examination rather than a replacement for it: the metadata reveals when and how the digital file was produced, while ink, paper, and signature analysis address the physical instrument if a hard copy also exists. Where both are available, cross-referencing digital and physical findings produces the most defensible conclusion — which is why UFC treats PDF metadata examination as a direct extension of its Forensic Document Examination practice, not a separate service.

Illustrative Matter · Nairobi · Land Sale Dispute

A Sale Agreement “Signed” Before Its Own Software Existed

A seller produced a signed sale agreement dated three years prior to support a competing claim over a residential plot. PDF property examination showed the Producer field naming a word-processing application version released after the claimed signing date, with a CreationDate falling within days of the court filing itself. Word revision metadata on a draft version supplied separately showed a single internal author account, unconnected to either party, with no earlier saved versions consistent with a three-year-old document.

Metadata inconsistency documented alongside physical document examination findings, supporting the buyer’s legal team in the land dispute proceedings.

Frequently Asked Questions

Can PDF metadata prove a contract was created after the date printed on it?

In most cases, yes. A PDF’s CreationDate and ModDate properties, together with the software identified in its Producer field, are set by the computer at the moment the file was actually generated — not by whatever date is typed into the visible document text. A contract “dated” three years ago but carrying a CreationDate from last month is a strong, independently verifiable inconsistency.

If someone printed and re-scanned a document to remove metadata, does that defeat forensic examination?

It removes the original digital metadata, but it creates new evidence instead. A print-scan cycle introduces its own scanner metadata, image compression artifacts, and often a loss of text-layer data that a genuinely digital-native document would have — all of which an examiner can use to show the document passed through an unexplained conversion step.

Does Microsoft Word keep a record of changes even after “Accept All Changes” is clicked?

Frequently, yes. Word documents are compressed archives of XML files, and remnants of revision history, prior authors, and comments can persist in a document’s internal structure even after the visible track-changes marks are cleared — particularly if the file was saved rather than freshly exported.

Can EXIF data from a photographed signature page really pinpoint when it was signed?

Often, yes. A photo taken on a smartphone typically embeds a capture timestamp, and sometimes GPS coordinates and device model, in its EXIF data — even when the image is later sent over WhatsApp or email. This can establish when and, at times, roughly where a signature page was actually photographed, independent of any date written on the document itself.

Suspect a Backdated or Forged Agreement?

Metadata evidence is strongest before a document is resaved, reprinted, or re-shared. Free, confidential case assessment for advocates, banks and corporates — response within 4 hours.